Blog

Thoughts on access control, AI governance, and the security problems worth solving.

OAuth Finds the SaaS Employees Sign Into. Our Chrome Extension Finds the Rest.

OAuth discovery surfaces every app authorized through Sign in with Google or Microsoft, with exact scopes. It cannot see the tools people sign up for with a work email and a password. Our new browser extension closes that gap, privacy first.

June 22, 2026 9 min read
Read

MCP Governance: How to Control What AI Agents Can Do in Your SaaS

AI agents now reach your SaaS through the Model Context Protocol. MCP governance is how you decide what they're allowed to do, prove what they did, and shut them off in seconds. What it is, why API keys aren't enough, the MCP gateway pattern, and a checklist.

June 18, 2026 10 min read
Read

Shadow AI: 80% of Your Employees Use It. You Approved 23%.

Shadow AI is shadow IT that reads your data and acts on your systems. Employees adopt AI faster than security can review it, and the newest tools take actions, not just answer questions. Why it spreads, what it costs, and how to govern it.

June 16, 2026 7 min read
Read

When the Employee Leaves but the Agent Stays

AI agents built by departing employees keep running after their creator's account is disabled. They still have access. Nobody owns them. Here is what to do about it.

June 3, 2026 6 min read
Read

How to Connect Claude to Slack via MCP with Access Controls

Step-by-step: install the Lutril MCP server, define a Slack access policy, register the agent, and test it. Policy-checked tool calls, a full audit trail, and a kill switch from the start.

June 3, 2026 8 min read
Read

Okta, Azure AD, and Lutril: Who Manages Access When AI Agents Enter the Picture?

Okta and Azure AD are excellent at managing human identity. Neither was designed for AI agents. Here is where each fits, where the gaps are, and why you probably need all three.

June 3, 2026 7 min read
Read

What Is the Access Layer for AI Agents?

AI agents need identity, policy enforcement, audit logs, and a kill switch before they touch your SaaS stack. That infrastructure has a name. Here is what it is and how it works.

June 3, 2026 6 min read
Read

Your IT Team Knows About 40 SaaS Apps. You Have 130.

Shadow IT is not a policy failure. It is the natural result of frictionless SaaS adoption. Here is why it keeps growing, what risk it creates, and what to do beyond writing a policy nobody reads.

June 3, 2026 5 min read
Read

Disabling an Okta Account Is Not Offboarding

41% of employees keep access to company systems after leaving. Most of that access sits in SaaS tools your IdP never touched. Here is what complete access revocation actually requires.

June 3, 2026 6 min read
Read

SOC 2 Wants Proof.
Not a Spreadsheet.

Most access reviews are a formality. Managers approve without context, shadow IT goes unreviewed, and evidence is thin. Here is what SOC 2 and ISO 27001 actually require, and what closing the gap looks like.

June 3, 2026 6 min read
Read

The AI Governance Gap

Your security stack controls who can access your SaaS tools. It has no idea your AI agents even exist. The problem, the three gaps, and what governance for agents actually looks like.

June 3, 2026 7 min read
Read